On this page
What CMMC Level 2 is
CMMC Level 2 is the level focused on protecting controlled unclassified information. The current official baseline is the 110 security requirements in NIST SP 800-171 Rev. 2, and DoD’s January 2026 FAQ says Rev. 3 has not yet become the assessment standard for Level 2.
That one point alone matters for accuracy and current-baseline clarity. A lot of marketing pages already blur Rev. 2 and Rev. 3 together. That is not the right current answer. If you are planning a Level 2 assessment in today’s environment, the working assessment baseline is still Rev. 2, even if your long-term program is watching Rev. 3.
The 14 domains at a glance
| Domain | What it covers in plain English |
|---|---|
| Access Control (AC) | Who gets in, what they can reach, and how access is limited. |
| Awareness & Training (AT) | Whether users understand their responsibilities and risks. |
| Audit & Accountability (AU) | Logging, audit records, and the ability to review activity. |
| Configuration Management (CM) | Standard settings, change control, and managed baselines. |
| Identification & Authentication (IA) | Credentials, MFA, and verifying identity. |
| Incident Response (IR) | Preparation, reporting, containment, and recovery steps. |
| Maintenance (MA) | Secure maintenance practices and control of tools and sessions. |
| Media Protection (MP) | Handling of removable media, printing, transport, and sanitization. |
| Personnel Security (PS) | Screening, onboarding, offboarding, and role changes. |
| Physical Protection (PE) | Physical access, facility controls, and visitor management. |
| Risk Assessment (RA) | Risk identification, vulnerability scanning, and corrective action. |
| Security Assessment (CA) | Assessment planning, monitoring, and system security planning. |
| System & Communications Protection (SC) | Boundary protections, encryption, segmentation, and transmission security. |
| System & Information Integrity (SI) | Malware protection, flaw remediation, and integrity monitoring. |
What assessors actually need to see
The official Level 2 Assessment Guide makes clear that assessors use examine, interview, and test methods. That means a company cannot rely on policy PDFs alone. It needs to show implemented controls, system configurations, operating records, screenshots, tickets, logs, and consistent operational practice.
In practical terms, a strong Level 2 readiness package usually includes a current asset inventory, network diagram, data-flow view, system security plan, policy and procedure set, user and admin lists, MFA evidence, configuration baselines, logging and alerting evidence, vulnerability and patch evidence, incident response records, backup evidence, media handling evidence, and a clean map to the 110 requirements.
Level 2 is more than a checklist
Companies often think the challenge is remembering 110 items. The real challenge is proving that the controls are operating in the actual scoped environment. A beautifully written SSP does not fix unmanaged local admin rights, weak MFA coverage, flat network access, unreviewed logs, uncontrolled removable media, or unknown vendor access.
Level 2 readiness works best when scoping, implementation, documentation, and evidence are treated as one connected program. Contractors do not just need someone who can talk about NIST. They need a practical path to turn the environment into something assessable.
The Rev. 2 vs Rev. 3 issue
DoD’s January 2026 FAQ addresses a major point of confusion. Although NIST SP 800-171 Rev. 3 exists, DoD has not yet incorporated it as the Level 2 assessment standard. The current assessment baseline remains Rev. 2. Companies can choose to work toward Rev. 3 in their own programs, but they still need to account for Rev. 2 and any official DoD overlays or procedures that apply today.
For planning purposes, do not assume Rev. 3 changed the current Level 2 assessment baseline. Treat Rev. 2 as the working assessment standard until DoD formally incorporates a different baseline through the required process.
What a buyer wants from a Level 2 partner
- A scoping workshop that shrinks the boundary where appropriate instead of blindly treating the entire company as in scope.
- A gap assessment that separates documentation gaps from technical control gaps.
- Hands-on remediation support for identity, endpoint, logging, segmentation, encryption, maintenance, and media handling.
- SSP and POA&M support tied to real evidence, not vague advisory language.
- Mock-assessment coaching so interviews, evidence requests, and walkthroughs do not become a surprise.
Frequently asked questions
How many requirements are in CMMC Level 2?
Level 2 uses the 110 security requirements in NIST SP 800-171 Rev. 2.
Does CMMC Level 2 still map to NIST SP 800-171 Rev. 2?
Yes. DoD’s January 2026 FAQ says Rev. 3 has not yet been incorporated as the Level 2 assessment standard, so the current baseline remains Rev. 2.
What evidence do assessors use at Level 2?
The official Assessment Guide says assessors use examine, interview, and test methods. In practice that means policy, procedure, system configuration, operational evidence, and user interviews all matter.
Do the 14 Level 2 domains come from NIST families?
Yes. The domains align with the NIST SP 800-171 Rev. 2 families.
Can we pass Level 2 with documentation alone?
No. Documentation is necessary, but assessors also look for implemented technical and operational evidence.
Does Level 2 automatically mean a C3PAO assessment?
No. Some Level 2 contracts require a self-assessment and others require a C3PAO certification assessment. The solicitation or contract determines which path applies.
How often do we repeat Level 2?
Level 2 assessments recur every three years, with annual affirmations of continued compliance in between.
What should we do first for Level 2 readiness?
Start with scoping. Then assess the 110 requirements against the real boundary, remediate gaps, and organize evidence before the formal assessment path begins.
Related articles
Official sources reviewed
Use this guide to plan readiness and communicate clearly with buyers, primes, and internal stakeholders. Contract language, current regulations, and assessor guidance control.
Want help turning this into a real readiness plan?
Velocity CMMC can scope the environment, map CUI flows, organize the documentation package, support remediation, and help your team prepare for the right assessment path without pretending to be the certifier.